skills/carlheath/ogmios/person-osint/Gen Agent Trust Hub

person-osint

Pass

Audited by Gen Agent Trust Hub on Jul 18, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exposes the agent to indirect prompt injection by design, as it requires the ingestion and analysis of untrusted data from various external web sources.- Ingestion points: The skill retrieves content from the open web, social media profiles, and professional databases using tools such as WebFetch, WebSearch, and specialized search/scraping MCPs.- Boundary markers: The instructions do not specify the use of delimiters or protective headers to prevent the agent from executing instructions that may be hidden within the scraped content.- Capability inventory: The agent has access to powerful tools like Bash and network search capabilities, which increases the potential impact if a hidden prompt is followed.- Sanitization: There is no evidence of a sanitization or validation phase to filter out malicious payloads or control sequences from the gathered intelligence.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 18, 2026, 12:06 AM
Security Audit — agent-trust-hub — person-osint